1

我是一个 PHP 黑客。非常感谢 Insight,因为它可以帮助我找出哪里出错了。

基本上,我出于自己的目的调整了此联系表。Javascript 验证效果很好!似乎 php 验证也正常工作。直到我开始从我自己的表单中收到空白提交。我试图避免在此表单中添加验证码。空白的提交很烦人,如果有人能指出我在改编中是否犯了错误,我会很高兴的。感谢您的时间。

表单 HTML

<?php include('/ajax/verify.php');?>
            <form action="/ajax/" method="post" id="sendEmail">

                <h4>Contact Us</h4>
                <p class="alert">* All fields are required</p>
                <ol class="forms">
                    <li><label for="username">Your Name</label><input type="text" name="username" id="username" value="" /></li>
                    <li><label for="emailFrom">Your Email</label><input type="text" name="emailFrom" id="emailFrom" value="" /></li>
                    <li><label for="phonenumber">Phone Number</label><input type="text" name="phonenumber" id="phonenumber" value="" /></li>
                    <li><label for="message">Message</label><textarea name="message" id="message"></textarea></li>
                    <li class="buttons"><button type="submit" id="submit">Send Email &raquo;</button><input type="hidden" name="submitted" id="submitted" value="true" /></li>
                </ol>
            </form>

Javascript 验证

//Ajax Form
$(document).ready(function(){
    $("#submit").click(function(){                                     
        $(".error").hide();
        var hasError = false;
        var emailReg = /^([\w-\.]+@([\w-]+\.)+[\w-]{2,4})?$/;
        var phoneReg = /^\(?(\d{3})\)?[- ]?(\d{3})[- ]?(\d{4})$/;

        //from email
        var emailFromVal = $("#emailFrom").val();
        if(emailFromVal == '') {
            $("#emailFrom").after('<span class="error">You forgot to enter the email address to send from.</span>');
            hasError = true;
        } else if(!emailReg.test(emailFromVal)) {   
            $("#emailFrom").after('<span class="error">Enter a valid email address to send from.</span>');
            hasError = true;
        }
        //name
        var usernameVal = $("#username").val();
        if(usernameVal == '') {
            $("#username").after('<span class="error">You forgot to enter your name.</span>');
            hasError = true;
        }
        //phone
        var phonenumberVal = $("#phonenumber").val();
        if(phonenumberVal == '') {
            $("#phonenumber").after('<span class="error">You forgot to enter your phone number.</span>');
            hasError = true;
        } else if(!phoneReg.test(phonenumberVal)) { 
            $("#phonenumber").after('<span class="error">Enter a valid phone number.</span>');
            hasError = true;
        }

        //message
        var messageVal = $("#message").val();
        if(messageVal == '') {
            $("#message").after('<span class="error">You forgot to enter the message.</span>');
            hasError = true;
        }


        if(hasError == false) {
            $(this).hide();
            $("#sendEmail li.buttons").append('<img src="/ajax/img/ajax-loader.gif" alt="Loading" id="loading" />');

            $.post("/ajax/sendEmail.php",
                { emailFrom: emailFromVal, username: usernameVal, phonenumber: phonenumberVal, message: messageVal },
                    function(data){
                        $("#sendEmail").slideUp("normal", function() {                 

                            $("#sendEmail").before('<h4 class="success">Thank You</h4><p class="success">One of our highly trained staff will contact with you shortly.</p>');                                          
                        });
                    }
                 );
        }

        return false;
    });                        
});

验证脚本 (php)

if(isset($_POST['submitted'])) {    
if($_POST['emailFrom'] == '') {
    $emailFromError = 'You forgot to enter the email address to send from.';
} else if (!eregi("^[A-Z0-9._%-]+@[A-Z0-9._%-]+\.[A-Z]{2,4}$", $_POST['emailFrom'])) {
    $emailFromError = 'Enter a valid email address to send from.';
}
if($_POST['phonenumber'] == '') {
    $emailFromError = 'You forgot to enter the email address to send from.';
} else if (!eregi("/^\(?(\d{3})\)?[- ]?(\d{3})[- ]?(\d{4})$/$", $_POST['phonenumber'])) {
    $emailFromError = 'Enter a valid email address to send from.';
}
if($_POST['message'] == '') {
    $messageError = 'You forgot to enter the message.';
}
if($_POST['username'] == '') {
    $messageError = 'You forgot your name.';
}

if(!isset($emailFromError) && !isset($messageError)) {
    include('sendEmail.php');
    include('thanks.php');
}

}

邮件脚本

$mailTo = 'redacted@emailaddress.com';
$mailFrom = $_POST['emailFrom'];
$username = $_POST['username'];
$phonenumber = $_POST['phonenumber'];
$subject = "New website inquiry from $username";
$message = $_POST['message'];
$message = wordwrap($message, 70);
$messagebody = "From: $username  Phone Number: $phonenumber $message"; 

mail($mailTo, $subject, $messagebody, "From: ".$mailFrom);
4

3 回答 3

1

您不仅需要在消息正文中查找空字符串,还需要删除所有空白字符(使用类似的内容trim()然后在其中查找内容。

就目前而言,有人可以简单地输入一些空白字符,它就会通过 PHP 验证。

最后,请记住,javascript 验证只是一种有用的速度提升,因为用户广告不可用于验证,因为我可以在关闭 javascript 的情况下使用您的网站。

于 2012-01-23T22:37:14.427 回答
1

在验证中,您可能想要执行以下操作:

foreach($_POST as $name => $value) {
    $_POST[$name] = trim($value);
}

验证看起来不错,但如果他们为您的所有必填字段放置一个空格,似乎可以通过空白提交。我不确定这是否正在发生,但从我在那里看到的情况来看,似乎空值不应该通过服务器端验证。

任何可能填写您的表单的机器人都会忽略 javascript,因此请确保服务器验证严格。

于 2012-01-23T22:37:46.987 回答
1

似乎(从文件名来看)如果有人禁用了 javascript,他或她将直接发布到邮件脚本并且没有进行服务器端验证。

你需要改变这个:

<form action="/ajax/sendEmail.php" method="post" id="sendEmail">

到:

<form action="/ajax/validation.php" method="post" id="sendEmail">

或调用任何您的验证脚本。

于 2012-01-23T22:37:50.897 回答